Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data.

The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4.

Released on

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze

Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling

Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling Meta has filed a patent application for an AI that listens to your voice throughout

LLMs could control their host machines by exploiting inference engines

LLMs could control their host machines by exploiting inference engines Source: Hacker News